WordPress Plugin Vulnerabilities

Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Unvalidated Attachment ID Reparenting

Description

The plugin does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.

Proof of Concept

Affects Plugins

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
PO-WEI TING (Dinlon5566), Open Information Security Inc.
Submitter
PO-WEI TING (Dinlon5566)
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-17 (about 9 hours ago)
Added
2026-09-17 (about 1 hour ago)
Last Updated
2026-09-17 (about 1 hour ago)

Other